Junglewise Threat Intelligence

CVE-2026-79227: Google Chrome type confusion in DevTools

CVE-2026-79227 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's developer tools contained a type confusion vulnerability that allowed attackers to execute arbitrary code within the browser's sandbox environment. By tricking users into visiting a specially crafted webpage, an attacker could exploit this flaw to run malicious code with the privileges of the browser process, potentially leading to data theft or system compromise.

Technical details

A type confusion vulnerability exists in Chrome's DevTools component that occurs when the browser incorrectly handles type checking of objects in memory. The vulnerability can be triggered remotely via a crafted HTML page and requires social engineering to deceive a user into opening the malicious content. Successful exploitation allows arbitrary code execution within the Chrome sandbox (CVE-2026-79227). The issue was patched in Chrome version 152.0.7977.65 released on August 25, 2026. While the Chromium project classified this as Medium severity, the CVSS score of 8.8 indicates significant impact potential.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats